<!-- Worked example: the output of tools/elf-report.sh against target/sample_app. -->
# Analysis: sample_app

Generated 2026-09-20T10:56:09+02:00 on 65-109-31-107.ptr (AlmaLinux 9.8 (Olive Jaguar), kernel 5.14.0-687.39.1.el9_8.x86_64)

| artefact | what it answers |
|---|---|
| [STATIC.md](STATIC.md) | what the binary *can* do - libs, imports, embedded paths |
| [REPORT.md](REPORT.md) | what it *did* - every file, process and socket (strace) |
| [preload/PRELOAD.md](preload/PRELOAD.md) | the same run at libc level, no ptrace |
| files.csv / processes.csv / network.csv | the same data for spreadsheets or diffing |
| strace.log | the raw evidence; every table above is derived from it |

## Declared vs actually loaded shared libraries

`ldd` lists 2 libraries; 3 distinct .so files were mapped at runtime.
Anything below was pulled in by `dlopen()` or by NSS/PAM plugins - static inspection alone would have missed it.

```
/usr/lib64/libtinfo.so.6.2
/work/acb/elf_analysis/target/libsampleplugin.so
```

## Files written, created or deleted

```
/dev/tty                                                     [write]
/tmp/sample_app.log                                          [create,write,stat,seek]
/tmp/sample_app.sock                                         [delete,open]
/tmp/sample_app.tmpdata                                      [create,write,delete,read,seek]
```

## Programs executed

```
pid 618047   /work/acb/elf_analysis/target/sample_app ["./sample_app"]
pid 618048   /work/acb/elf_analysis/target/sample_helper ["./sample_helper", "/etc/services"]
pid 618049   /bin/sh                                  (then re-exec'd)
pid 618049   /usr/bin/uname                           ["/usr/bin/uname", "-r"]
```

2 process(es) were created by the target (fork/clone).

## Paths probed but absent (ENOENT)

These are the config, plugin and $PATH locations the program would have honoured had they existed.

```
/etc/sample_app/secrets.conf
/root/.local/bin/sh
/root/.vscode-server/cli/servers/Stable-a44adf7f53e00964ab890f9f8758a334f1fc15bc/server/bin/remote-cli/sh
/root/bin/sh
/tmp/sample_app.sock
/usr/condabin/sh
/usr/local/bin/sh
/usr/local/sbin/sh
/usr/sbin/sh
/usr/share/Modules/bin/sh
/work/acb/semgrep-offline/.venv/bin/sh
```

## Network activity

```
bind       {sa_family=AF_UNIX, sun_path="/tmp/sample_app.sock"}, 110 -> 0
listen     1 -> 0
connect    {sa_family=AF_INET, sin_port=htons(9), sin_addr=inet_addr("127.0.0.1")}, 16 -> ECONNREFUSED
```

## Automatic flags

```
/bin/sh                                                    a shell was exec'd - check where the command string comes from
/etc/passwd                                                enumerates local accounts
```

_Flags are heuristics over one run. Absence of a flag is not a clean bill of health: you only see the code paths your arguments exercised._

## Checklist for the written-up finding

- [ ] Does it write outside its own data directory (/etc, /usr, another user's $HOME)?
- [ ] Does it read credentials (/etc/shadow, ~/.ssh, *.pem, *.key, token files)?
- [ ] Does it exec a shell, or anything whose path comes from the environment ($PATH lookup)?
- [ ] Does it connect outbound, and to a hardcoded address?
- [ ] Does it dlopen a library from a writable directory (hijackable)?
- [ ] Do the ENOENT probes point at config it would honour if you created it?
- [ ] Re-run with different arguments/environment - coverage is only what you exercised.
